Cleartext Storage Vulnerability in Netis WF-2404 Router
CVE-2025-2922
What is CVE-2025-2922?
A vulnerability has been identified in the Netis WF-2404 router, specifically within an unknown functionality of the BusyBox Shell. This flaw results in the cleartext storage of sensitive information, potentially exposing critical data. Attackers with physical access to the device may exploit this weakness, albeit the complexity and difficulty of executing an attack are relatively high. Despite the disclosure of the exploit to the public, the vendor has not responded to reports of this issue, leaving users at risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WF-2404 1.1.124EN
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
